Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-6073

iPXE efi binaries are not signed with the Red Hat key

    • None
    • None
    • rhel-sst-network-drivers
    • ssg_networking
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      ipxe is the preferred option for the network bootloader for automated bare metal provisioning. Increasingly customers are requesting support for UEFI Secure Boot to be enabled. However currently Secure Boot must be switched off during the provisioning process because the ipxe efi binaries are not signed.

      This is a request for the ipxe efi files to be signed with pesign during packaging (like the grub2 package).

      This would allow customers to include the Red Hat key in a custom Secure Boot policy and enable Secure Boot. It would also be the first step in getting the shim to somehow boot into ipxe instead of grub.

              mschmidt@redhat.com Michal Schmidt
              rhn-engineering-sbaker Steve Baker
              Michal Schmidt Michal Schmidt
              Oliver Gutiérrez Suárez Oliver Gutiérrez Suárez
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: